Critical Severity Vulnerability
This vulnerability has been rated as Critical severity. Immediate action is recommended.
CVE-2016-0746
CriticalVulnerability Description
Use-after-free vulnerability in the resolver in nginx 0.6.18 through 1.8.0 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (worker process crash) or possibly have unspecified other impact via a crafted DNS response related to CNAME response processing.
CVSS Metrics
Common Vulnerability Scoring System
Vector String:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Known Affected Software
355 configuration(s) from 5 vendor(s)
cpe:2.3:a:apple:xcode:6.1.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:7.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:7.3:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:4.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:4.0.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:3.1.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:1.5.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:4.6:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:7.2:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:4.2:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:8.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:4.3.3:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:7.1.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:5.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:11.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:4.6.3:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:2.3.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:6.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:4.3.2:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:11.2:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:6.3.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:2.4.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:9.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:9.3.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:6.3:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:3.2.2:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:2.1.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:3.2.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:3.2.4:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:4.3.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:7.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:7.3.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:8.3.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:3.2.3:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:5.0.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:5.0.2:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:3.1.3:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:7.0.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:6.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:10:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:5.1.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:9.0.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:4.6.2:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:11.3:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:4.6.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:8.2:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:6.3.2:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:12.5:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:3.1.2:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:12.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:9.3:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:4.2.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:4.4.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:4.3:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:12.5.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:4.5.2:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:4.5:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:3.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:4.1.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:6.2:beta_2:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:2.2.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:4.5.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:9.4:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:4.4:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:9.4.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:8.3.3:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:2.4.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:7.2.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:8.3:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:9.2:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:3.2.5:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:4.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:5.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:9.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:6.4:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:8.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:8.2.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:8.3.2:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:6.0.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:4.0.2:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:3.1.4:*:*:*:*:*:*:*
cpe:2.3:a:apple:xcode:12.4:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.0.12:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.55:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.16:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.42:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.6.28:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.39:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.6.20:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.50:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.7.12:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.1.6:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.9.2:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.4:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.7.9:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.3.8:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.1.4:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.53:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.6.24:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.3.5:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.4:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.5.9:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.0.13:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.1.7:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.35:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.2.7:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.14:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.21:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.0.15:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.6.22:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.6.32:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.5.11:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.3.15:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.5.6:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.9:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.5.10:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.9.4:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.3.16:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.3.13:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.62:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.7.4:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.17:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.40:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.13:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.6.1:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.1:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.41:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.1.8:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.7.10:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.6.34:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.37:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.1.15:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.48:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.7.11:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.1.1:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.6:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.20:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.0.7:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.5.12:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.4.6:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.59:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.10:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.32:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.25:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.1.14:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.1.19:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.5.8:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.5:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.3.12:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.0.14:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.58:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.8:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.9.1:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.6.29:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.6.18:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.3:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.5.2:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.6.37:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.3.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.18:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.9.3:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.0.6:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.9.7:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.9.5:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.52:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.51:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.2.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.6.19:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.17:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.6.31:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.6.39:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.34:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.9.2:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.68:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.63:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.20:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.46:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.40:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.22:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.7.6:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.31:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.38:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.4.4:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.6.36:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.34:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.31:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.1.17:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.1.16:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.28:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.9.6:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.2.5:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.5.4:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.5.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.56:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.28:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.49:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.24:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.9.7:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.1.13:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.24:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.8:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.6.26:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.8.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.9.6:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.2.6:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.2.2:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.43:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.3.11:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.46:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.54:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.14:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.23:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.1.3:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.0.9:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.4.3:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.60:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.1.11:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.61:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.37:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.0.8:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.19:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.3.1:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.7.5:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.4.1:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.27:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.7.7:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.9.1:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.3.10:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.9:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.4.5:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.9.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.53:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.23:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.4.2:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.51:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.5.13:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.69:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.6.21:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.3.4:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.43:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.11:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.65:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.12:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.9.5:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.6.33:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.54:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.3.2:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.7.8:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.19:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.6.2:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.27:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.18:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.1.12:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.6.38:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.33:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.36:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.39:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.26:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.2.4:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.47:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.6.30:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.6.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.3.9:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.7:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.9.3:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.66:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.3.6:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.36:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.30:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.12:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.2.1:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.45:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.45:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.47:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.2:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.9.9:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.1.18:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.25:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.3.14:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.4.7:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.67:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.6.3:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.22:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.48:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.52:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.0.5:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.55:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.2.3:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.29:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.5.7:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.33:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.26:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.9.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.1.2:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.0.11:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.15:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.6.23:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.6:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.35:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.7:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.50:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.10:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.2.8:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.32:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.41:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.44:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.3.7:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.11:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.13:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.5.1:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.0.4:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.0.3:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.15:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.1.10:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.38:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.16:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.5:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.21:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.5.5:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.29:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.44:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.7.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.30:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.3:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.9.8:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.57:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.6.25:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.6.35:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.64:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.1:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.1.9:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.1.5:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.6.27:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.42:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.49:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.0.10:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.5.3:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.3.3:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.9.4:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.2.9:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.2:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*
References & Resources
-
http://lists.opensuse.org/opensuse-updates/2016-02/msg00042.htmlsecalert@redhat.com Mailing List Third Party Advisory
-
http://mailman.nginx.org/pipermail/nginx/2016-January/049700.htmlsecalert@redhat.com Vendor Advisory
-
http://seclists.org/fulldisclosure/2021/Sep/36secalert@redhat.com Mailing List Third Party Advisory
-
http://www.debian.org/security/2016/dsa-3473secalert@redhat.com Third Party Advisory
-
http://www.securitytracker.com/id/1034869secalert@redhat.com Third Party Advisory VDB Entry
-
http://www.ubuntu.com/usn/USN-2892-1secalert@redhat.com Third Party Advisory
-
https://access.redhat.com/errata/RHSA-2016:1425secalert@redhat.com Third Party Advisory
-
https://bto.bluecoat.com/security-advisory/sa115secalert@redhat.com Third Party Advisory
-
https://bugzilla.redhat.com/show_bug.cgi?id=1302588secalert@redhat.com Issue Tracking Patch Third Party Advisory
-
https://security.gentoo.org/glsa/201606-06secalert@redhat.com Third Party Advisory
-
https://support.apple.com/kb/HT212818secalert@redhat.com Third Party Advisory
-
http://lists.opensuse.org/opensuse-updates/2016-02/msg00042.htmlaf854a3a-2127-422b-91ae-364da2661108 Mailing List Third Party Advisory
-
http://mailman.nginx.org/pipermail/nginx/2016-January/049700.htmlaf854a3a-2127-422b-91ae-364da2661108 Vendor Advisory
-
http://seclists.org/fulldisclosure/2021/Sep/36af854a3a-2127-422b-91ae-364da2661108 Mailing List Third Party Advisory
-
http://www.debian.org/security/2016/dsa-3473af854a3a-2127-422b-91ae-364da2661108 Third Party Advisory
-
http://www.securitytracker.com/id/1034869af854a3a-2127-422b-91ae-364da2661108 Third Party Advisory VDB Entry
-
http://www.ubuntu.com/usn/USN-2892-1af854a3a-2127-422b-91ae-364da2661108 Third Party Advisory
-
https://access.redhat.com/errata/RHSA-2016:1425af854a3a-2127-422b-91ae-364da2661108 Third Party Advisory
-
https://bto.bluecoat.com/security-advisory/sa115af854a3a-2127-422b-91ae-364da2661108 Third Party Advisory
-
https://bugzilla.redhat.com/show_bug.cgi?id=1302588af854a3a-2127-422b-91ae-364da2661108 Issue Tracking Patch Third Party Advisory
-
https://security.gentoo.org/glsa/201606-06af854a3a-2127-422b-91ae-364da2661108 Third Party Advisory
-
https://support.apple.com/kb/HT212818af854a3a-2127-422b-91ae-364da2661108 Third Party Advisory
Severity Details
Weakness Type (CWE)
Use After Free
- Description
- The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations…
- Exploit Likelihood
- High
- Typical Severity
- High
- Abstraction Level
- Variant
Key Information
- Published Date
- February 15, 2016
